fedora-list at redhat.com

ryan ryanag at zoominternet.net
Sun Mar 13 10:16:01 UTC 2005


"How do I lock or disable unused ports such as keyboard, video and USB 
ports?

 
Here is the scenario; I have several firewalls built upon Fedora that are in
closets physically unmonitored.  An unscrupulous individual could plug in a
keyboard, mouse and monitor into one of these systems and start getting
access to it.  Even worse the individual could plug in other devices to log
all packets flowing through the firewall.   This gives me chills just
thinking about it!
 
I would like to disable any I/O devices that aren't actually needed."  
 

Way too much work with no tangible benefits. If you did all this, what is to keep a malicious attacker from dropping in a $10 hub, then setting up a monitoring station. He/She could just walk in occaisionally and get the logs off, or worse, set up a cheap access point and just pull into the parking lot, SSH into their sniffer machine, and get the logs that way.

Physically secure the machines or don't think too hard about it. Stripping the servers down to a CPU/RAM/HD and ethernet ports won't provide much additional security.





More information about the fedora-list mailing list